CVE-2018-14592

CRITICAL

CWJoomla <2.0.7, <1.0.6 - SQL Injection

Title source: llm

Description

The CWJoomla CW Article Attachments PRO extension before 2.0.7 and CW Article Attachments FREE extension before 1.0.6 for Joomla! allow SQL Injection within download.php.

Exploits (1)

exploitdb WORKING POC
by Haboob Team · textwebappsphp
https://www.exploit-db.com/exploits/45447

Scores

CVSS v3 9.8
EPSS 0.0346
EPSS Percentile 87.6%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Products (2)
cwjoomla/cw_article_attachments_free < 1.0.6
cwjoomla/cw_article_attachments_pro < 2.0.7
Published Sep 20, 2018
Tracked Since Feb 18, 2026